FATCA and CRS compliance certification: what it requires, where it applies, and why it matters

For most of the history of FATCA and the Common Reporting Standard, compliance has been understood primarily as a reporting exercise. Financial institutions collect due diligence information on their account holders, identify reportable accounts, generate the required XML files, and submit them to the competent authority by the applicable deadline. The cycle repeats annually. The measure of compliance is whether the return was filed on time.

That understanding is increasingly incomplete. A growing number of jurisdictions have introduced formal annual compliance certification requirements that go well beyond the submission of a reporting return. These frameworks require financial institutions to attest to the quality of the processes, governance structures, and documentation that sit behind what they file. Competent authorities use the information to assess compliance posture, assign risk ratings, and prioritise supervisory activity. The annual return is the output. The certification is an assessment of the machinery that produced it.

This article explains what these certification frameworks require, where they currently apply, and what the competent authorities do with the information they receive.

Bermuda: Annual CRS Compliance Certification

The Bermuda Corporate Income Tax Agency was designated as the competent authority for FATCA and CRS purposes in March 2026, taking over from the Bermuda Monetary Authority. One of CITA's first substantive actions was to introduce the Annual CRS Compliance Certification Form, due by 30 September each year beginning in 2026.

The certification applies to all Bermuda Reporting Financial Institutions and Trustee-Documented Trusts. It requires institutions to certify their compliance posture across a structured set of questions covering the existence and adequacy of written FATCA and CRS policies and procedures, the performance of annual compliance training for relevant staff, the adequacy of due diligence procedures for new and pre-existing accounts, the quality and completeness of self-certifications obtained from account holders, the accuracy of historical FATCA and CRS filings, and the existence of an appropriate governance framework for FATCA and CRS oversight at senior management and board level.

The certification is not a simple declaration. It requires the institution to have conducted a structured self-assessment of its compliance framework before completing the form. CITA has made clear that it will use the certifications to identify institutions for independent compliance reviews. Selected institutions are required to engage an approved independent reviewer to assess the adequacy of their FATCA and CRS compliance framework and produce a written report. The certification is therefore the entry point into a risk-based supervisory process, not a formality.

The practical consequence for institutions that have been treating FATCA and CRS as a pure reporting exercise is significant. A certification that reveals gaps in written procedures, inadequate self-certification practices, or an absence of board-level governance will not simply result in a low score. It will trigger a review. The quality of what sits behind the annual return now has direct supervisory consequences.

BVI: CRS Additional Information Form

The BVI International Tax Authority introduced its own compliance certification requirement in April 2025 through the CRS Additional Information Form, with the first annual deadline falling on 30 September 2025 and the second on 30 September 2026, covering the year ended 31 December 2025.

The form applies to all BVI financial institutions, both Reporting Financial Institutions and Non-Reporting Financial Institutions, and must be submitted through the BVIFARS portal. It consists of 19 questions covering the institution's regulatory classification and status under the CRS, the number and categorisation of financial accounts held, self-certification practices for new and pre-existing accounts including the percentage of accounts for which valid self-certifications are on file, the existence of written policies and procedures, the frequency and content of staff training, and the accuracy and completeness of historical CRS filings.

The ITA uses the responses to assign a risk rating of low, medium, or high to each institution. The rating has direct supervisory consequences. Institutions assigned a low risk rating are subject to periodic monitoring with no immediate intervention. Institutions assigned a medium risk rating may face desk-based compliance reviews every one to two years. Institutions assigned a high risk rating face annual reviews until compliance is demonstrated to the ITA's satisfaction, with on-site inspections possible at any stage.

The BVI framework is notable for its explicit link between the quality of self-certification practices and the risk rating assigned. An institution that cannot demonstrate that it has obtained valid self-certifications for a high proportion of its account holders, or that lacks written procedures for managing self-certification failures, is likely to receive a medium or high risk rating regardless of the accuracy of its historical CRS filings. The form is designed to assess the robustness of the underlying due diligence process, not merely the completeness of the output.

Cayman Islands: CRS Compliance Form

The Cayman Islands Department for International Tax Cooperation introduced its CRS Compliance Form requirement significantly earlier than Bermuda and BVI, having implemented it alongside the annual CRS return from 2018 onwards. From the 2026 reporting year, both the CRS Return and the CRS Compliance Form are due by 30 June of the following year, consolidated into a single deadline through the DITC portal.

The Cayman Islands compliance form covers similar ground to the BVI form: entity classification, account data quality, self-certification practices, policies and procedures, and governance. The DITC has consistently emphasised that it focuses on the quality of CRS data rather than simply its volume, and has published detailed guidance on common compliance failures identified through its review of submitted returns and compliance forms.

The Cayman Islands framework has the additional feature of requiring institutions to notify the DITC of material errors or omissions in previously submitted returns as they are identified, rather than waiting for the next annual cycle. This ongoing correction obligation reinforces the message that compliance is a continuous process rather than an annual event.

Malta: Self-Compliance Questionnaire

The Malta Tax and Customs Administration introduced its annual Self-Compliance Questionnaire for FATCA and CRS purposes on 23 February 2026 through an update to its implementing guidelines under Subsidiary Legislation 123.127. The SCQ applies to all financial institutions within the scope of FATCA and CRS in Malta, both Reporting and Non-Reporting Financial Institutions, and must be submitted annually through the MTCA's dedicated online portal. The first submission deadline was 13 March 2026, covering the 2025 reporting period. The deadline is expected to fall in March annually thereafter.

The questionnaire covers entity classification and registration status, the existence of written FATCA and CRS policies and procedures tailored to the institution's business model, the performance of annual compliance training, self-certification practices for new and pre-existing accounts, the clear allocation of responsibilities at board and senior management level, and the accuracy of historical FATCA and CRS filings.

What makes the Malta framework particularly significant is what happened after the first round of submissions. In June 2026, the MTCA published a circular summarising the outcome of the 2026 SCQ exercise. While responses indicated broad awareness of FATCA and CRS obligations across the sector, the MTCA identified a series of areas requiring improvement. Governance arrangements were found to be inconsistently formalised or embedded at board level. Written policies and procedures, where they existed, were not always tailored to the institution's specific business model. Self-certification practices showed gaps, particularly for pre-existing accounts. The MTCA made clear that it expects these findings to be addressed before the next submission cycle and that ongoing monitoring will focus on how institutions evidence the effective implementation of their obligations, not merely their awareness of them.

Malta's SCQ is also notable for being an EU member state taking this step at a time when most other EU jurisdictions rely on annual reporting alone. Its introduction in the same year as Malta's transposition of DAC8 through Legal Notice 162 of 2026 signals that the MTCA intends to apply the same governance-focused approach to crypto-asset reporting obligations as it has developed for FATCA and CRS.

What competent authorities do with the information

The information collected through compliance certification frameworks serves three distinct purposes, each of which has direct consequences for financial institutions.

The first is risk prioritisation. Competent authorities use the certifications to identify which institutions present the highest compliance risk and should therefore be the subject of more intensive supervisory activity. An institution that certifies strong written procedures, comprehensive self-certification practices, regular staff training, and accurate historical filings is likely to receive a low risk designation and face minimal supervisory intervention. An institution that reveals gaps in any of these areas is directing the competent authority's attention toward itself.

The second is data quality improvement. By requiring institutions to certify the quality of their due diligence procedures before submitting their annual returns, competent authorities are directly improving the reliability of the information they receive and subsequently exchange with partner jurisdictions. A self-certification that is obtained improperly, or not at all, produces a reportable account with unreliable or missing tax residency information. The certification frameworks are designed to reduce the frequency and impact of this problem by making institutions attest to the adequacy of their practices before the data enters the exchange process.

The third is protection of account holders and their information. The automatic exchange of FATCA and CRS information is one of the most significant tools available to tax authorities for identifying undeclared assets and income held offshore. For this system to function as intended, the information being exchanged must be accurate and complete. An account holder whose self-certification contains errors, or who has not been properly identified as a reportable person, may have information exchanged with the wrong jurisdiction or not at all. Competent authorities that invest in compliance certification frameworks are, in effect, protecting the integrity of the information that account holders have provided and ensuring that it is used correctly.

The broader significance

The jurisdictions that have introduced formal FATCA and CRS compliance certification frameworks share a common characteristic: they have moved from treating compliance as a reporting obligation to treating it as a governance obligation. The distinction matters. A reporting obligation is met when the return is filed. A governance obligation requires the institution to maintain, document, and attest to the quality of an ongoing compliance programme that produces accurate reporting as its output.

Luxembourg, France, and most other continental European jurisdictions currently require financial institutions to maintain a record of the due diligence actions undertaken in respect of each account. This is a meaningful requirement but it falls short of a formal annual certification, a risk-rating framework, or an independent review process. The direction of travel in the jurisdictions that have gone further is clear: compliance certification is becoming the standard, not the exception.

For financial institutions with structures or clients in Bermuda or the BVI, the 30 September 2026 deadline is the immediate priority. For those with Cayman Islands exposure, the 30 June 2027 deadline for the 2026 reporting year is the next relevant date. For those operating in Malta, the next SCQ submission is expected in March 2027, covering the 2026 reporting period, and the MTCA's June 2026 circular has already signalled the areas it will be watching most closely.

Next
Next

DAC8 and the end of information asymmetry in crypto taxation